Re: BIND 9.10 compilation problem for FreeBSD 6.x/7.x

2014-05-07 Thread Tony Finch
Mark Andrews ma...@isc.org wrote: Also one shouldn't need to add LDFLAGS=-R/opt/OpenSSL/lib. configure adds it itself if the platform needs it. --with-openssl=/opt/OpenSSL should be enough. I think the bug here is that configure assumes the admin has added all possible library directories to

RPZ and www.rackspace.com

2014-05-07 Thread David A. Evans
We have just enabled RPZ with some NSDNAME checks and are seeing an issue resolving www.rackspace.com. The first lookup is successful and returns both the CNAME and the A record. The second query, within a second of the first, will only return the CNAME. It will only return

Re: RPZ and www.rackspace.com

2014-05-07 Thread Phil Mayers
On 07/05/14 15:05, David A. Evans wrote: Can anyone else verify this behavior? What is going on with www.rackspace.com? If this is a miss configuration on Rackspace's DNS servers how are they not getting hit with support calls like crazy? We don't have any NSDNAME RPZ entries,

Re: RPZ and www.rackspace.com

2014-05-07 Thread David A. Evans
No, *rackspace* appears nowhere in our RPZ feeds save the new entry that works around the issue. This entry excludes it from hitting the RPZ zone with the NSDNAME records via a PASSTHRU line a earlier RPZ zone. David A. Evans Enterprise IP/DNS Management Network Infrastructure

Re: RPZ and www.rackspace.com

2014-05-07 Thread David A. Evans
I've done some more troubleshooting with info from people that responded directly to me and not to the list.This can be reproduced without any RPZ loaded by mimicking the behavior of the RPZ lookups required to validate NSDNAME lines. Issue these 'digs' within 30 second of each

Re: RPZ and www.rackspace.com

2014-05-07 Thread Mark Andrews
In message ofdc3c86d9.d668b707-on86257cd1.005339fc-86257cd1.00543...@notes.cat.com, David A. Evans writes: I've done some more troubleshooting with info from people that responded directly to me and not to the list.This can be reproduced without any RPZ loaded by mimicking

Re: Multi-master (HA)

2014-05-07 Thread John Wingenbach
I run a multi-master environment. We have 3 data centers which are considered to be able to run even though the rest are down. Initially, we ran our masters with the same exact configurations on each. One of the data centers was administratively defined as being the 'update master'. From

Re: Multi-master (HA)

2014-05-07 Thread fddi
I run bind multi master on 5 different site. my solution is bind-dlz with galeraDB backed. we are very satisfied by this configuration and works flawlessy until now. Rick On 5/7/14 8:11 PM, John Wingenbach wrote: I run a multi-master environment. We have 3 data centers which are considered

Re: Multi-master (HA)

2014-05-07 Thread Lawrence K. Chen, P.Eng.
On 05/06/14 13:39, Evan Hunt wrote: On Tue, May 06, 2014 at 06:20:11PM +, Baird, Josh wrote: Hi, For those of you who operate at multiple sites or datacenters, are you doing any HA for your BIND masters? Ideally, we would have a master in each datacenter; maybe not an active one, but

Re: Point domain name of my zone to name in somebody else's zone?

2014-05-07 Thread Lawrence K. Chen, P.Eng.
DNAME ? On 05/06/14 11:44, Rom, Gloria wrote: Yup, that’s what I was asking. Thanks. Gloria Rom UCLA Library Digital Initiatives and Information Technology glor...@library.ucla.edu mailto:glor...@library.ucla.edu 310-206-9784 *From:*bind-users-boun...@lists.isc.org

Re: Point domain name of my zone to name in somebody else's zone?

2014-05-07 Thread Mark Andrews
In message 536aaf39.6000...@ksu.edu, Lawrence K. Chen, P.Eng. writes: DNAME ? No. DNAME redirects the names under it. It does not redirect the owner name. On 05/06/14 11:44, Rom, Gloria wrote: Yup, that=92s what I was asking. Thanks. = = = Gloria Rom = UCLA Library

Re: Point domain name of my zone to name in somebody else's zone?

2014-05-07 Thread Lawrence K. Chen, P.Eng.
Oh...I misread the questionguess DNAME isn't what's wanted just the apex to somewhere else Yeah...I currently just look up the name and enter A records. But, I've wondered if there was another record type that allowed it to detect address changes of the requested 'CNAME'so I

Re: RRL active by default?

2014-05-07 Thread Lawrence K. Chen, P.Eng.
Can't seem to figure out how to work something like that into my configuration. It doesn't like that I have allow-recursion { k-state; }; set in optionsthen something about when using 'view' statements, all zones must be in views. So, I uncommented the view ksu { lines in my config (there

Re: Multi-master (HA)

2014-05-07 Thread Peter Andreev
Well, we use two masters in different locations, w/o DLZ. Files for signed zones are being generated from databases and uploaded to servers. What we need here - is propagating of DDNS plus periodical synchronizing of zones, journals etc. Regarding zone templates - I'm using it with NSD4 and I'm

Re: Point domain name of my zone to name in somebody else's zone?

2014-05-07 Thread Barry Margolin
In article mailman.160.1399503258.26362.bind-us...@lists.isc.org, Lawrence K. Chen, P.Eng. lkc...@ksu.edu wrote: Oh...I misread the questionguess DNAME isn't what's wanted just the apex to somewhere else Yeah...I currently just look up the name and enter A records. But, I've